CVE-2018-0003
published 2018-01-10CVE-2018-0003: A specially crafted MPLS packet received or processed by the system, on an interface configured with MPLS, will store information in the system memory…
PriorityP426medium6.5CVSS 3.0
AVAACLPRNUINSUCNINAH
EPSS
0.91%
56.4th percentile
A specially crafted MPLS packet received or processed by the system, on an interface configured with MPLS, will store information in the system memory. Subsequently, if this stored information is accessed, this may result in a kernel crash leading to a denial of service. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D71; 12.3 versions prior to 12.3R12-S7; 12.3X48 versions prior to 12.3X48-D55; 14.1 versions prior to 14.1R8-S5, 14.1R9; 14.1X53 versions prior to 14.1X53-D45, 14.1X53-D107; 14.2 versions prior to 14.2R7-S7, 14.2R8; 15.1 versions prior to 15.1F5-S8, 15.1F6-S8, 15.1R5-S6, 15.1R6-S3, 15.1R7; 15.1X49 versions prior to 15.1X49-D100; 15.1X53 versions prior to 15.1X53-D65, 15.1X53-D231; 16.1 versions prior to 16.1R3-S6, 16.1R4-S6, 16.1R5; 16.1X65 versions prior to 16.1X65-D45; 16.2 versions prior to 16.2R2-S1, 16.2R3; 17.1 versions prior to 17.1R2-S2, 17.1R3; 17.2 versions prior to 17.2R1-S3, 17.2R2; 17.2X75 versions prior to 17.2X75-D50. No other Juniper Networks products or platforms are affected by this issue.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos_os | — | — |
| juniper_networks | junos_os | >= 12.1X46 < 12.1X46-D71 | 12.1X46-D71 |
| juniper_networks | junos_os | >= 12.3 < 12.3R12-S7 | 12.3R12-S7 |
| juniper_networks | junos_os | >= 12.3X48 < 12.3X48-D55 | 12.3X48-D55 |
| juniper_networks | junos_os | >= 14.1 < 14.1R8-S5, 14.1R9 | 14.1R8-S5, 14.1R9 |
| juniper_networks | junos_os | >= 14.1X53 < 14.1X53-D45, 14.1X53-D107 | 14.1X53-D45, 14.1X53-D107 |
| juniper_networks | junos_os | >= 14.2 < 14.2R7-S7, 14.2R8 | 14.2R7-S7, 14.2R8 |
| juniper_networks | junos_os | >= 15.1 < 15.1F5-S8, 15.1F6-S8, 15.1R5-S6, 15.1R6-S3, 15.1R7 | 15.1F5-S8, 15.1F6-S8, 15.1R5-S6, 15.1R6-S3, 15.1R7 |
| juniper_networks | junos_os | >= 15.1X49 < 15.1X49-D100 | 15.1X49-D100 |
| juniper_networks | junos_os | >= 15.1X53 < 15.1X53-D65, 15.1X53-D231 | 15.1X53-D65, 15.1X53-D231 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Juniper
CVE-2018-0003: A specially crafted MPLS packet received or processed by the system, on an interface configured with MPLS, will store information in the system memory
vendor_juniper·2018-01-10·CVSS 6.5
CVE-2018-0003 [MEDIUM] CVE-2018-0003: A specially crafted MPLS packet received or processed by the system, on an interface configured with MPLS, will store information in the system memory
CVE-2018-0003: A specially crafted MPLS packet received or processed by the system, on an interface configured with MPLS, will store information in the system memory. Subsequently, if this stored information is accessed, this may result in a kernel crash leading to a denial of service. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D71; 12.3 versions prior to 12.3R12-S7; 12.3X48 versions prior to 12.3X48-D55; 14.1 versions prior to 14.1R8-S5, 14.1R9; 14.1X53 versions prior to 14.1X53-D45, 14.1X53-D107; 14.2 versions prior to 14.2R7-S7, 14.2R8; 15.1 versions prior to 15.1F5-S8, 15.1F6-S8, 15.1R5-S6, 15.1R6-S3, 15.1R7; 15.1X49 versions prior to 15.1X49-D100; 15.1X53 versions prior to 15.1X53-D65, 15.1X53-D231; 16.1 versions prior to 16.1R3-S6, 16.1R4-S6, 1
GHSA
GHSA-x2pc-9r6q-7m2m: A specially crafted MPLS packet received or processed by the system, on an interface configured with MPLS, will store information in the system memory
ghsa_unreviewed·2022-05-13
CVE-2018-0003 [MEDIUM] GHSA-x2pc-9r6q-7m2m: A specially crafted MPLS packet received or processed by the system, on an interface configured with MPLS, will store information in the system memory
A specially crafted MPLS packet received or processed by the system, on an interface configured with MPLS, will store information in the system memory. Subsequently, if this stored information is accessed, this may result in a kernel crash leading to a denial of service. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D71; 12.3 versions prior to 12.3R12-S7; 12.3X48 versions prior to 12.3X48-D55; 14.1 versions prior to 14.1R8-S5, 14.1R9; 14.1X53 versions prior to 14.1X53-D45, 14.1X53-D107; 14.2 versions prior to 14.2R7-S7, 14.2R8; 15.1 versions prior to 15.1F5-S8, 15.1F6-S8, 15.1R5-S6, 15.1R6-S3, 15.1R7; 15.1X49 versions prior to 15.1X49-D100; 15.1X53 versions prior to 15.1X53-D65, 15.1X53-D231; 16.1 versions prior to 16.1R3-S6, 16.1R4-S6, 16.1R5; 16.1X65
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-12189 jboss: unsafe chown of server.log in jboss init script allows privilege escalation (Incomplete fix for CVE-2016-8656)
bugzilla·2017-10-09·CVSS 7.0
CVE-2017-12189 [HIGH] CVE-2017-12189 jboss: unsafe chown of server.log in jboss init script allows privilege escalation (Incomplete fix for CVE-2016-8656)
CVE-2017-12189 jboss: unsafe chown of server.log in jboss init script allows privilege escalation (Incomplete fix for CVE-2016-8656)
It was reported that the jbossas init script performed unsafe file handling, which could result in local privilege escalation.
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2018:0003 https://access.redhat.com/errata/RHSA-2018:0003
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6
Via RHSA-2018:0002 https://access.redhat.com/errata/RHSA-2018:0002
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7
Via RHSA-2018:0004 https://access.
Bugzilla
CVE-2017-7561 resteasy: Vary header not added by CORS filter leading to cache poisoning
bugzilla·2017-08-22·CVSS 7.5
CVE-2017-7561 [HIGH] CVE-2017-7561 resteasy: Vary header not added by CORS filter leading to cache poisoning
CVE-2017-7561 resteasy: Vary header not added by CORS filter leading to cache poisoning
The CORS Filter did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances.
Resteasy versions >=3.0.7 are affected because they include the CORS Filter.
Discussion:
Acknowledgments:
Name: Jason Shepherd (Red Hat Product Security)
---
RHMAP using RestEasy in UPS, but does not use CorsFilter class. Marking as not affected
---
Fixed upstream in Resteasy 4.0.0 via https://issues.jboss.org/browse/RESTEASY-1704
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2018:0003 https://access.redhat.com/errata/RHSA-2018:0003
---
This
2018-01-10
Published